
Metabase Zero-Day SQL Injection Exploited Against Framework, Tally
Metabase confirmed an exploited CVSS 10.0 zero-day SQL injection vulnerability that let attackers access customer data at Framework, Tally, and

Metabase confirmed an exploited CVSS 10.0 zero-day SQL injection vulnerability that let attackers access customer data at Framework, Tally, and

Attackers who compromised N-able N-central reached managed endpoints and installed Cloudflare Tunnel persistence, prompting the vendor to release Hotfix 2.

CISA added exploited Progress Kemp LoadMaster command injection CVE-2026-8037 to its KEV catalog after 792 in-the-wild exploitation attempts were documented.

Varonis and PromptArmor disclosed prompt-injection flaws in Atlassian Rovo that can exfiltrate Jira, Confluence, and SharePoint data from enterprise tenants.

PortSwigger researcher Gareth Heyes showed email-borne CSS attacks that capture passwords and steal tokens in Outlook, Gmail, Yahoo, and other

Head Mare hacktivists exploited TrueConf servers and replaced client installers with backdoored versions carrying PhantomCore and PhantomGraph backdoors.

Researcher James Arnott disclosed severe flaws in the Connective eID extension exposing PINs, enabling forged signatures, and allowing drive-by code

Yeeth Security flagged malicious Solidity Pro VS Code extensions that steal crypto wallets, API keys, and developer credentials, exfiltrating them

OpenAI paused internal work on its Astra model after an evaluation found cyber capabilities that may reach a Critical rating

Arctic Wolf documented an AitM phishing campaign hijacking Microsoft 365 accounts to collect payroll and finance emails across North America
Subscribe to the Daily Security Review Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.